7.8
CVSSv2

CVE-2008-3526

Published: 27/08/2008 Updated: 13/02/2023
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

Integer overflow in the sctp_setsockopt_auth_key function in net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel 2.6.24-rc1 up to and including 2.6.26.3 allows remote malicious users to cause a denial of service (panic) or possibly have unspecified other impact via a crafted sca_keylength field associated with the SCTP_AUTH_KEY option.

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel 2.6.24.7

linux linux kernel 2.6.24.2

linux linux kernel 2.6.25.5

linux linux kernel 2.6.24

linux linux kernel 2.6.24.1

linux linux kernel 2.6.26

linux linux kernel 2.6.26.3

linux linux kernel 2.6.25.9

linux linux kernel 2.6.25.13

linux linux kernel 2.6.25.3

linux linux kernel 2.6.26.2

linux linux kernel 2.6.25.15

linux linux kernel 2.6.24_rc4

linux linux kernel 2.6.26.1

linux linux kernel 2.6.25.8

linux linux kernel 2.6.24.4

linux linux kernel 2.6.24.5

linux linux kernel 2.6.24_rc1

linux linux kernel 2.6.25.10

linux linux kernel 2.6.25.1

linux linux kernel 2.6.25.4

linux linux kernel 2.6.24.6

linux linux kernel 2.6.24_rc5

linux linux kernel 2.6.25.11

linux linux kernel 2.6.24.3

linux linux kernel 2.6.25

linux linux kernel 2.6.25.2

linux linux kernel 2.6.25.7

linux linux kernel 2.6.25.14

linux linux kernel 2.6.25.12

linux linux kernel 2.6.25.6

Vendor Advisories

Synopsis Important: kernel security and bug fix update Type/Severity Security Advisory: Important Topic Updated kernel packages that fix several security issues and several bugsare now available for Red Hat Enterprise MRG 10This update has been rated as having important security impact by the RedHat Secur ...
It was discovered that the direct-IO subsystem did not correctly validate certain structures A local attacker could exploit this to cause a system crash, leading to a denial of service (CVE-2007-6716) ...